Add colleagues or external auditors to your Nexxis organisation with appropriate role permissions.
Nexxis uses role-based access control (RBAC). You can invite team members with specific roles to limit what they can view and edit.
| Role | What They Can Do |
|---|---|
| Owner | Full access — manage billing, settings, users, all projects |
| Admin | Manage users and projects, cannot change billing |
| Editor | Create/edit workflows and reports; cannot manage users |
| Viewer | Read-only access to reports and control status |
| Auditor | Read-only + can download evidence packages |
**For external auditors:** Use the **Auditor** role. They can view evidence and download packages but cannot edit anything.
When a team member leaves, remove them from Settings → Team immediately. Their sessions are invalidated within 5 minutes.